Talos Takes: 2025's ransomware trends and zombie vulnerabilities

2026-04-07T20:51:57Zad25e779d3fba001168602598f996ce4ae84334f335f672bd26d0e3d2825ba0d
AxiosCanvaEDR-evasionHikVisionLog4jNEXUS-ListenerPHPUnitQilinReact2ShellTP-LinkUAT-10608business-email-compromisecredential-harvestingnpm-compromisephishingransomwaresaas-notification-abusesupply-chainvulnerabilities

What happened

Cisco Talos RSS roundup covering the 2025 Year in Review and multiple active threat trends: rising ransomware activity (including Qilin ransomware and EDR-evasion via msimg32.dll), large-scale credential harvesting campaign tracked as UAT-10608 using the “NEXUS Listener” framework, increased abuse of SaaS notification pipelines for phishing/spam, notable supply-chain incidents (Axios NPM), and disclosure of numerous vendor vulnerabilities (TP-Link, Canva, HikVision) alongside legacy ‘zombie’ vulnerabilities (Log4j, PHPUnit, React2Shell). The feed emphasizes elevated attacker use of identity, E

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
ad25e779d3fba001168602598f996ce4ae84334f335f672bd26d0e3d2825ba0d
Enrichment time
2026-04-07T20:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Talos Takes: 2025's ransomware trends and zombie vulnerabilities · Baitaphish